VDB
Sign up
MEDIUM6.1

GHSA-px3r-jm9g-c8w8

rails-html-sanitizer Cross-site Scripting vulnerability

Quick fix

GHSA-px3r-jm9g-c8w8 — rails-html-sanitizer: upgrade to the fixed version with the command below.

bundle update rails-html-sanitizer

Details

There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rails-html-sanitizer
Introduced in: 0Fixed in: 1.0.4
Fixbundle update rails-html-sanitizer

References